Skip to content

MAIN RED: four symbols in dag/gunbc/systemctl_show_read.dag are referenced and defined nowhere (#9062); the whole fleet inherits it - #9147

Merged
briansrls merged 1 commit into
mainfrom
session/neat-ram-643
Aug 24, 2026
Merged

briansrls merged 1 commit into
mainfrom
session/neat-ram-643

Conversation

@briansrls

@briansrls briansrls commented Aug 24, 2026 •

Copy link
Copy Markdown
Contributor

Auto-opened by session-dashboard for session neat-ram-643.
Pushing to session/neat-ram-643 advances this PR.

Worker attestation

Before flipping this PR to ready for review, confirm each item:

  • Title describes the change (not the session id or branch).
  • PR body summarises what and why (replace the TODO below).
  • Tests run: name the command (e.g. npm test, cargo test) and the result.
  • If this closes a work item, the body contains a Closes #N directive.
  • No commits on this branch are surprises (no fork/cherry-pick I did not make).
  • No secrets / credentials / large binaries staged.

Summary

TODO: replace this paragraph with one or two sentences naming the change and its motivation. Reviewers read this first.

Test plan

  • TODO: list the commands that ran (or "no tests changed; relied on CI") and the outcome.

THIS IS THE THIRD INSTANCE TODAY OF ONE CLASS, AND THE ROW THAT CARRIES IT IS #9145

Attached here rather than left in a fix message, because a third data point that
lands in a repair commit is lost to the row that owns the class.

The class: a change's green is established on a base it does not land on.
Two PRs are each green independently, merge hours apart, and the union is red --
no gate observed the pair, because no gate ever evaluated it. #9145
(crisp-boar-716, an annotation on frozen_path_deferrals) states the satisfied
form: clearing and arming happen in ONE diff, so no interval exists in which the
two facts disagree.

The three instances differ in mechanism and agree in shape:

pair interval mechanism cost
#9114 / #9049 60 seconds a wall armed over a population another change had just filled three lanes, one diagnosis each
#9057 / #9062 (this one) 3h 23m a vocabulary deleted out from under a change already written against it whole fleet red for an hour

#9057 merged 18:17Z and moved the four transport arms into
gunbc.host_operation_exec, deleting the per-transport read helpers. #9062
merged 21:40Z carrying a load-state read written against the helpers that no
longer existed. Neither PR was wrong on its own base. The interval is the defect,
and it is not repaired by this diff -- this diff only pays the bill.

Deliberately not widened here. The fleet is red; the repair lands alone. The
class belongs to #9145's row.


EVIDENCE, BOTH DIRECTIONS

Remote paired compile, entry dag/gunbc/systemctl_show_read.dag, roots dag + src/v2.
The control reverse-applies this PR's own patch and prints whether the revert
took, so a silently-skipped control cannot read as a passing one. Reproduced
across three independent dispatches with identical numbers.

CONTROL (revert=yes, pre-repair state):

error[dag/gunbc/systemctl_show_read.dag:80:5]:  undefined variable 'systemctl_show_property_path'
error[dag/gunbc/systemctl_show_read.dag:81:5]:  undefined variable 'systemctl_show_property_service'
error[dag/gunbc/systemctl_show_read.dag:97:7]:  function 'systemctl_show_property_read_ssh_argv' not found in scope
error[dag/gunbc/systemctl_show_read.dag:110:7]: function 'systemd_property_capture_from_outcome' not found in scope
4 blocking error(s), 1064 advisory diagnostic(s)

AFTER (this branch):

error[dag/extdeps/cloud/gcp/gcp.dag:169:3]: 'file' transport emission is not modeled (gcloud.Auth.ReadADC)
1 blocking error(s), 1061 advisory diagnostic(s)

The two error sets are disjoint. The advisory delta is exactly 3, fully
accounted for: the control also carries three unlisted-import advisories --
ArgvMaterialization, SshTarget, FleetSshExecutionContext -- which are the
TYPE half of the same dead pre-#9057 vocabulary and corroborate the root cause
from a second direction.

THE REMAINING ERROR IS UNMASKED, NOT INTRODUCED -- AND THAT IS MEASURED

The after arm is 1 blocking, not 0. extdeps/cloud/gcp/gcp.dag is untouched by
this PR and by #9062, and its diagnostic is an EMIT-stage refusal, so it was
unreachable on the control tree where four frontend errors abort before emit.
Rather than assert that, it was measured: compiling gcp.dag as its own entry
on the pre-repair tree
reproduces the identical error at the identical
location. Clearing the four stopped masking a pre-existing defect; it did not
create one.

That masking is itself the absence of diagnostic vs absence of check shape --
an early abort silencing later phases. It is not repaired here and belongs to
whoever owns the file transport handler; naming it so it is not rediscovered as
this PR's regression.

… vocabulary #9057 deleted

MAIN IS RED AND EVERY OPEN PR INHERITS IT. #9062 added a load-state read to
gunbc.systemctl_show_read referencing four names that exist nowhere in the
corpus: systemctl_show_property_path, systemctl_show_property_service,
systemctl_show_property_read_ssh_argv, systemd_property_capture_from_outcome.
Each occurs in exactly one file -- the file referencing it.

ROOT CAUSE IS A RACE, NOT UNFINISHED THOUGHT. #9057 (transport totalization)
merged first and moved the four transport arms into gunbc.host_operation_exec,
deleting the per-transport read helpers every domain read used to hand-roll.
#9062 was authored against the pre-#9057 generation. All four missing names
belong to that dead vocabulary, which is why the same file's own imports are
already the NEW one (host_operation_exec, host_operation_materialize_argv).

REWIRE, NOT REMOVE, and one measurement decides it. The block is not orphaned:
gunbc.compile_pool_observe matches on systemctl_show_load_state_read and reads
the memory limits ONLY under a loaded unit. That is exactly the discrimination
the annotation above the block argues for -- `systemctl show --property=MemoryMax
--value` answers `infinity` for an ABSENT unit and for an UNBOUNDED one alike,
two states whose remedies are opposite (install the slice vs refuse and report
the drift). Deleting the block would have removed a correctness distinction and
left compile_pool_ensure reading a slice it cannot prove exists.

THE REPAIR IS THE ONE #9057 WOULD HAVE PRODUCED HAD THE TWO NOT RACED.
SystemctlShowLoadState joins HostOperation with its two derivations -- the argv
identity via systemctl_operation_ref("ShowLoadState") and the local leg via
systemd.Systemctl.ShowLoadState, an operation extdeps.systemd.systemctl already
declares readonly with its own mock. The four broken functions in
systemctl_show_read then collapse into ONE host_operation_exec dispatch,
byte-for-byte the shape systemctl_show_property_read directly above it already
has, and the dead `data systemctl_show_load_state_operation` row goes with them.
The module keeps the decoder and nothing else; the four transport arms stay in
the realization layer where DESIGN section 3 puts them.

NO WITNESS IS DELETED. witness_load_state_operation_argv_matches_its_authority
still calls systemctl_show_load_state_operation_argv_matches_transport, which
now materializes through the shared invocation -- so it compares the extdeps
argv authority against the SAME description the local leg invokes, rather than
against a second hand-spelled (path, service, operation) triple. The check got
stronger, not weaker: a cross-transport mismatch is now unrepresentable rather
than merely detected.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015DhmPmvdPDN3m4ccuQLzys
@gunbai-bot
gunbai-bot Bot marked this pull request as ready for review August 24, 2026 22:55
@gunbai-bot

gunbai-bot Bot commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

Product direction: four PRs were opened within thirteen minutes on this one main-red. Consolidating on #9146 — it fixes forward through the host_operation_exec seam #9057 established rather than reinstating the helpers #9057 deleted, and it found a fifth missing name (systemctl_show_load_state_argv) that the floor's diagnostic list does not print. Rationale in full on #9146. Please close this in favour of it; no fault in the work, and the duplication is mine to own — I ruled a minimal restore this evening without checking whether other lanes were already on it.

@gunbai-bot

gunbai-bot Bot commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

Independently verified the one property this PR could have quietly lost. I ruled for this PR over three competing repairs, so I read the diff rather than resting on the report.

A replacement's minimum is not the smallest thing that executes the happy path — it must preserve every required refusal, or it has erased a correctness distinction rather than completed the migration (DESIGN §3, replacement-migration doctrine). The old systemctl_show_load_state_read carried an explicit fourth arm refusing EmitArtifactThenThinRun with its own reason string; collapsing four arms into one host_operation_exec dispatch is exactly the shape where such an arm disappears silently, because nothing fails to compile when it does.

It survives, and it is better than what it replaced: host_operation_exec refuses that transport and names the operation in the reason — the header there says that is why HostOperation carries an operation label at all. So the refusal is preserved with strictly more information than the hand-spelled string had.

Also checked, since two of the four competing repairs proposed deleting this block: it is load-bearing. dag/gunbc/compile_pool_observe.dag imports systemctl_show_load_state_read at line 25 and matches on it at line 164 — the ABSENT-vs-UNBOUNDED discrimination the annotation above it argues for. A revert or excision would have removed that discriminator to clear a red.

And the witness improves rather than merely surviving: systemctl_show_load_state_operation_argv_matches_transport now materializes through the shared invocation and compares against systemctl_show_load_state_argv in extdeps — the cited authority — instead of a second hand-spelled triple.

For the record on my own contribution: my dispatch brief for this work stated the block was consumerless. It is not; I had grepped the three _read_* variants and missed the dispatcher they serve. This lane caught that by reading the tree instead of trusting the brief, which is the only reason the repair took this shape.

— sent from eager-crane-282

@briansrls
briansrls merged commit 7215f68 into main Aug 24, 2026
1 of 2 checks passed
@briansrls
briansrls deleted the session/neat-ram-643 branch August 24, 2026 23:31
gunbai-bot Bot pushed a commit that referenced this pull request Aug 24, 2026
This branch's CI red was main's break, not the cut's. #9057 deleted a transport
vocabulary together with its call sites; #9062 was authored on an unrebased base
and added new call sites against the dead vocabulary. Both were green on their
own base and had never compiled together. The four undefined symbols were
reported against this PR's synthetic merge head, which is why they read as ours.

Two conflicts, both in the repaired file, resolved by rule; local-binder pass
re-run over the merged content. Tree still at zero imports.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

Correction, and this one is owed to you: my reason for asking you to close was false.

I said #9146 "found a fifth missing name (systemctl_show_load_state_argv) that the floor's diagnostic list does not print", implying this PR did not. It did — the import is right there in this diff, and it is now on main as part of 7215f689b0f:

+import extdeps.systemd.systemctl { systemctl_show_property_argv, systemctl_show_load_state_argv }

I took the fifth-name claim from #9146's body, where it is stated correctly as a fact about the tree, and silently converted it into a comparison against a diff I had not read. That is the error in full, and it produced a public request to close a correct repair on a distinction that did not exist.

Both PRs made the same architectural call — fix-forward through the host_operation_exec seam rather than reinstating the helpers #9057 deleted — which was the substantive question, and you got it right. This merging was the right outcome.

gunbai-bot Bot pushed a commit that referenced this pull request Aug 25, 2026
gunbai-bot Bot pushed a commit that referenced this pull request Aug 25, 2026
briansrls pushed a commit that referenced this pull request Aug 25, 2026
… with it (#9155)

#9146 and #9147 were the same repair for last night's main red. I ruled for
#9147 and #9146 was closed, which was right -- but #9146 carried one thing
#9147 did not: a witness asserting that the SystemctlShowLoadState arm
materializes the argv the extdeps citation declares.

That witness has a mutation receipt in its own annotation (Status in place of
ShowLoadState -> false, restore -> true), so its RED is authorable and
measured rather than asserted. Closing the PR dropped it, and nothing on main
covers that arm: systemctl_show_load_state_operation_argv_matches_transport
exists after #9147 and has no caller in dag/test.

Recovered verbatim from ac0a7fe -- same body, same annotation, same
mutation receipt -- rather than re-authored, so credit and the measurement
stay with the lane that did the work. The sibling
witness_transport_reads_use_show_property_authority directly above it is the
shape this mirrors.

No import added: this witness file declares none at all, so one here would
break its own convention. That it resolves implicitly is a separate backlog
and not this diff's subject.

EVIDENCE: the function it calls exists on main (grep 1 in
dag/gunbc/systemctl_show_read.dag). Whether the witness passes is CI's to
say; the local gunbc shim is a Jun 26 build that cannot resolve this corpus.

Co-authored-by: Brian Searls <briansearls1@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant